Privacy Policy
Privacy Policy – The Church PT
Last updated: Monday 8th September 2025
This Privacy Policy explains how The Church PT (“the Studio”, “we”, “us”, “our”) collects, uses, and protects your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information We Collect
We may collect and process the following information about you:
-
Personal details: name, address, email, phone number, date of birth.
-
Health information: medical history, injuries, conditions, and other information provided on health questionnaires or during consultations.
-
Booking & payment details: session bookings, payment records, and related financial transactions.
-
Communication records: emails, messages, or forms submitted to us.
-
CCTV: where used on-site for security and safety.
-
With prior consent, photos or videos may occasionally be taken during sessions for social media content. In some instances, instructors may also wish to share promotional material on their personal or studio social media accounts.
2. How We Use Your Information
We use your personal data to:
-
Manage bookings, payments, and services..
-
Provide safe and appropriate personal training, Pilates, therapies, and related services.
-
Communicate with you about sessions, events, or changes to services.
-
Comply with legal, insurance, and health & safety obligations.
-
Improve our services and facilities.
-
Send marketing communications (only with your consent, which you can withdraw at any time).
3. Legal Basis for Processing
We process your data under one or more of the following lawful bases:
-
Contract: to provide the services you have booked.
-
Legal obligation: to comply with UK law (e.g., health & safety, tax records).
-
Legitimate interests: to operate and improve our services.
-
Consent: for collecting health information and for sending marketing communications.
4. Sharing Your Information
We do not sell or rent your data. We may share data only with:
-
Trainers, therapists, or staff who need it to provide services.
-
Payment processors and booking platforms.
-
Professional advisers (e.g., insurers, accountants) where necessary.
-
Authorities if required by law.
Where therapists operate as independent contractors, your data may be shared with them securely for the purposes of your treatment.
5. Data Storage & Security
-
Data is stored securely in physical and/or electronic form.
-
We use appropriate technical and organisational measures to protect against loss, misuse, or unauthorised access.
-
Health and consent forms may be retained in locked storage or secure digital systems.
6. Data Retention
-
General booking and payment records: retained for at least 6 years (for accounting/legal purposes).
-
Health and medical records: retained for up to 7 years after your last session (in line with insurance requirements).
-
Marketing data: retained until you withdraw consent.
7. Your Rights
Under UK GDPR, you have the right to:
-
Access the personal data we hold about you.
-
Request correction of inaccurate or incomplete data.
-
Request deletion of your data (where legally possible).
-
Restrict or object to processing.
-
Withdraw consent at any time (e.g., for marketing).
-
Data portability (receive a copy of your data in a usable format).
To exercise your rights, please contact us at info@thechurchpt.com / 01204 936 452
8. Cookies & Website
If we operate a website, cookies may be used to improve your experience. You will be able to manage your preferences when visiting our site.
9. Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact:
The Church PT
Edgworth Methodist Church, Edgworth, Bolton, BL7 0AH
info@thechurchpt.com
01204 936 452
10. Complaints
If you are not satisfied with how we handle your data, you can complain to the Information Commissioner’s Office (ICO) at www.ico.org.uk.